Hawthorne · OAuth Scopes

Hawthorne OAuth Scopes

OAuth 2.0 searched

Hawthorne publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Hawthorne API on a user’s behalf.

Tokens are issued from https://shopify.com/authentication/57105744010/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyE-CommerceRetailConsumer GoodsPersonal CareGroomingAgentic CommerceShopify
Scopes: 4 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://shopify.com/authentication/57105744010/oauth/authorize
Token URL
https://shopify.com/authentication/57105744010/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid OpenID Connect authentication; issue an ID token for the customer.
email Access the authenticated customer's email address.
customer-account-api:full Full access to the Shopify Customer Account API on behalf of the signed-in customer.
customer-account-mcp-api:full Full access to the customer-account MCP API surface (agent-driven commerce).

Source

OAuth Scopes

hawthorne-scopes.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://hawthorne.co/.well-known/openid-configuration
docs: https://shopify.dev/docs/api/customer
notes: >-
  OAuth/OIDC scopes advertised by the store's Shopify Customer Account API
  discovery document. These are Shopify platform scopes surfaced on the Hawthorne
  shop host, not a bespoke Hawthorne scope registry. The customer-account-mcp-api
  scope gates the store's agent-facing MCP commerce endpoint.
schemes:
- name: ShopifyCustomerAccountOIDC
  source: well-known/hawthorne-openid-configuration.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://shopify.com/authentication/57105744010/oauth/authorize
    tokenUrl: https://shopify.com/authentication/57105744010/oauth/token
scopes:
- scope: openid
  description: OpenID Connect authentication; issue an ID token for the customer.
  sources: [well-known/hawthorne-openid-configuration.json]
- scope: email
  description: Access the authenticated customer's email address.
  sources: [well-known/hawthorne-openid-configuration.json]
- scope: customer-account-api:full
  description: Full access to the Shopify Customer Account API on behalf of the signed-in customer.
  sources: [well-known/hawthorne-openid-configuration.json]
- scope: customer-account-mcp-api:full
  description: Full access to the customer-account MCP API surface (agent-driven commerce).
  sources: [well-known/hawthorne-openid-configuration.json]